CVE-2023-53213Out-of-bounds Read in Linux

CWE-125Out-of-bounds Read5 documents5 sources
Severity
7.1HIGHNVD
EPSS
0.0%
top 97.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 15

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: slab-out-of-bounds read in brcmf_get_assoc_ies() Fix a slab-out-of-bounds read that occurs in kmemdup() called from brcmf_get_assoc_ies(). The bug could occur when assoc_info->req_len, data from a URB provided by a USB device, is bigger than the size of buffer which is defined as WL_EXTRA_BUF_MAX. Add the size check for req_len/resp_len of assoc_info. Found by a modified version of syzkaller. [ 46.592467][ T

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:HExploitability: 1.8 | Impact: 5.2

Affected Packages4 packages

NVDlinux/linux_kernel4.154.19.283+7
Debianlinux/linux_kernel< 5.10.191-1+3
CVEListV5linux/linuxcf2b448852abd47cee21007b8313fbf962bf3c9aac5305e5d227b9af3aae25fa83380d3ff0225b73+9
debiandebian/linux< linux 6.1.27-1 (bookworm)

Patches

🔴Vulnerability Details

2
OSV
CVE-2023-53213: In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: slab-out-of-bounds read in brcmf_get_assoc_ies() Fix a slab-out-of2025-09-15
GHSA
GHSA-fq2q-2mv8-c2mg: In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: slab-out-of-bounds read in brcmf_get_assoc_ies() Fix a slab-out-2025-09-15

📋Vendor Advisories

2
Red Hat
kernel: wifi: brcmfmac: slab-out-of-bounds read in brcmf_get_assoc_ies()2025-09-15
Debian
CVE-2023-53213: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: brcmf...2023
CVE-2023-53213 — Out-of-bounds Read in Linux | cvebase